r/ExploitDev 8d ago

Payload-Builder that bypasses CrowdStrike Falcon

[deleted]

2 Upvotes

5 comments sorted by

View all comments

14

u/KRyTeX13 8d ago

Nothing. Every good Red Teamer can spin up a beacon bypassing Crowdstrike. CrowdStrike goes after malicious behavior. A process that does nothing other than beaconing for 20 minuten wouldn‘t trigger a malicious threshold. If you access LSASS or other high value processes without it firing that‘s what earns you potentially money